PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-7615 kasparsd CVE debrief

The Widget Context plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.3.3. This is due to missing or incorrect nonce validation on the save_widget_context_settings function. This makes it possible for unauthenticated attackers to modify widget visibility context settings stored in the WordPress options table via a forged POST request to /wp-admin/widgets.php via a forged request granted they can trick a site administrator into performing an action such as clicking on a link. The CVE record was published on 2026-05-22T09:16:32.250Z and has not been modified since then. The NVD entry is currently Deferred.

Vendor
kasparsd
Product
Widget Context
CVSS
MEDIUM 4.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-05-22
Original CVE updated
2026-07-23
Advisory published
2026-05-22
Advisory updated
2026-07-23

Who should care

Administrators of WordPress installations with the Widget Context plugin installed should be aware of this vulnerability and take steps to mitigate it. They should review their current plugin version and update to a fixed version if necessary. Additionally, they should monitor for suspicious activity and restrict access to the WordPress administration area.

Technical summary

The vulnerability exists in the Widget Context plugin for WordPress, specifically in the save_widget_context_settings function, where nonce validation is missing or incorrect. This allows unauthenticated attackers to modify widget visibility context settings via a forged POST request to /wp-admin/widgets.php. The issue affects all versions up to, and including, 1.3.3 of the plugin. Evidence is limited to CVE and NVD information, with the CVE record published on 2026-05-22T09:16:32.250Z and last modified on 2026-07-23T16:10:00.137Z. The NVD entry is currently Deferred. Administrators should review their current plugin version and update to a fixed version if necessary.

Defensive priority

Medium High

Recommended defensive actions

  • Update the Widget Context plugin to a version that includes a fix for this vulnerability.
  • Implement additional security measures, such as monitoring for suspicious activity and restricting access to the WordPress administration area.
  • Verify that the plugin is properly configured and that all settings are secure.
  • Review compensating controls for exposed systems while remediation is scheduled and verified.
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review.
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented.
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.

Evidence notes

The CVE record was published on 2026-05-22T09:16:32.250Z and was last modified on 2026-07-23T16:10:00.137Z. The NVD entry is currently Deferred. The vulnerability exists in the Widget Context plugin for WordPress, specifically in the save_widget_context_settings function, where nonce validation is missing or incorrect. This allows unauthenticated attackers to modify widget visibility context settings via a forged POST request. Evidence is limited to CVE and NVD information.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-05-22T09:16:32.250Z and has not been modified since then. The NVD entry is currently Deferred.